Information Security Assurance Manager

BAM UK & Ireland
Hemel Hempstead, Hertfordshire
6 months ago
Applications closed

Related Jobs

View all jobs

Security Assurance Manager

Experis City of London, United Kingdom

Cyber Advisory - Manager

Forvis Mazars Ludgate Hill, City And County Of the City Of London, United Kingdom

Operational Technology Risk Manager

MBDA Middle Hulton, Manchester, BL5 1FJ, United Kingdom
£60,000 pa Hybrid Clearance Required

Operational Technology Risk Manager

MBDA Manchester, United Kingdom
£60,000 pa

Consultant, Readiness Services , GBR)

CrowdStrike United Kingdom
Remote

Sr. Analyst, Falcon Complete , GBR)

CrowdStrike United Kingdom
Remote
Posted
31 Oct 2025 (6 months ago)

Building a sustainable tomorrow

BAM UK & Ireland are recruiting an Information Security Assurance Manager to join the team. This role can be based out of any of our UK office locations. There may be a requirement for occasional travel to other BAM offices, which may involve overnight stays. BAM supports flexible working and operates a hybrid working model between home and office for this role.

Your mission

You will be Contributing to the development, implementation and enforcement of information security policies, procedures and measures to ensure the confidentiality, integrity and availability of the IT systems and business information. Help manage various audits in the organisation on an annual basis.

• Work with key stakeholders in the business, IT team and externally where required.
• Identifying and registering new and emerging risks and trends in the field of information security and developing appropriate measures.
• Develop and maintain security risk frameworks, policies, and standards, aligned with regulatory and industry best practices (e.g., ISO 27001, NIST CSF).
• Taking care of management and documentation of Information Security Management System.
• Managing external audits like CE+,ISO27001 as per the Group requirements of maintaining security certifications.
• Partner with internal audit, compliance, and enterprise risk functions to ensure a coordinated approach to risk management.
• Support in answering appropriate information issues in tenders and various other government projects.
• Performing third party risk assessments of external suppliers to make sure they are compliant.
• Managing and promote security awareness programme Group Wide.
• Executing phishing campaigns, communications and remedial actions.
• Drawing up reports and dashboards on the basis of approved KPIs and KRIs.

Who are we looking for?

• Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent.
• Strong knowledge of information security frameworks and standards (ISO 27001, NIST, COBIT, CIS Controls).
• Third party risk management.
• Proven experience in second line of defence, risk management, assurance, or audit functions.
• A professional and mature attitude to deal with a range of internal and external stakeholders.
• Understanding and practical experience in the application of data protection and other related legislation, standards and codes of practice.
• Ability to work independently, manage competing priorities, and deliver high-quality assurance outputs.
• Team-oriented and able to collaborate with different departments.
• Excellent organisational and communication skills.

What’s in it for you?

We offer a competitive salary and benefits package, which includes a company car, matched pension contributions, private healthcare, life assurance, 26 days holiday, overtime, travel time, on call and sick pay. In addition to an attractive salary and benefits package, we support further personal, professional, technical and leadership development.

Your work environment

People are at the heart of what we do at BAM. We recognise that creating a diverse and inclusive environment that nurtures our employees and encourages them to bring their best and whole self to work is crucial. We’re on an exciting journey to get us there by recruiting the very best talent to join us regardless of race, colour, religion, national or ethnic origin, sexual orientation, gender identity or expression, age, disability or other characteristics.

Be you! Join us today, so we can achieve amazing things together and build a sustainable tomorrow.

Who are we?

The art of building is about building for communities; it’s about building for life.

Where others stop, we go further, leading the way towards a sustainable tomorrow for us and future generations. As an industry leader, we raise the bar.

Our values: sustainable, inclusive, collaborative, reliable and ownership, enable us to achieve our ambitions. Today, tomorrow and every day.

Our recruitment process, what you need to know?

BAM is committed to ensuring a fully inclusive recruitment and onboarding process, so if at any time you feel we need to do something to make it more accessible to you, do not hesitate to speak with one of our team, and we will do our best to support you. "Join us in Making Posssible

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Advertising cyber security jobs in the UK requires a different approach to most technical hiring. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.

Penetration Tester Jobs in the UK: What Employers Actually Want in 2026

The demand for skilled professionals in cyber security has never been higher, and penetration testers sit at the very heart of this rapidly evolving industry. As organisations across the UK continue to digitise their operations, protect sensitive data, and defend against increasingly sophisticated threats, the need for ethical hackers has grown dramatically. If you are considering a career in this field—or looking to advance within it—it is essential to understand what employers are really looking for in 2026. This guide breaks down the current expectations, required skills, certifications, and practical experience that can help you stand out in a competitive job market.